Skip to content

Commit 9fcd861

Browse files
ci: use reusable workflow for semgrep (#436)
Updated the build-test-release workflow to use [sast-scan](https://github.com/splunk/sast-scanning) owned by product security team instead of using custom implementation. Ref: https://splunk.atlassian.net/browse/ADDON-72309
1 parent d156287 commit 9fcd861

File tree

1 file changed

+3
-8
lines changed

1 file changed

+3
-8
lines changed

.github/workflows/build-test-release.yaml

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -62,14 +62,9 @@ jobs:
6262
- uses: pre-commit/action@v3.0.0
6363

6464
semgrep:
65-
runs-on: ubuntu-latest
66-
name: security-sast-semgrep
67-
steps:
68-
- uses: actions/checkout@v4
69-
- id: semgrep
70-
uses: semgrep/semgrep-action@v1
71-
with:
72-
publishToken: ${{ secrets.SEMGREP_PUBLISH_TOKEN }}
65+
uses: splunk/sast-scanning/.github/workflows/sast-scan.yml@main
66+
secrets:
67+
SEMGREP_KEY: ${{ secrets.SEMGREP_PUBLISH_TOKEN }}
7368

7469
run-unit-tests:
7570
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)